Lotus Notes/Domino LDAP Service Vulnerabilities
BID:7039
Info
Lotus Notes/Domino LDAP Service Vulnerabilities
| Bugtraq ID: | 7039 |
| Class: | Unknown |
| CVE: |
CVE-2001-1311 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | The vulnerabilities were discovered using the PROTOS project's LDAPv3 test suite. |
| Vulnerable: |
Lotus Notes Client 5.0.5 Lotus Notes Client 5.0.4 Lotus Notes Client 5.0.3 Lotus Notes Client 5.0.2 Lotus Notes Client 5.0.1 Lotus Notes Client 5.0 Lotus Notes Client R5 Lotus Domino 5.0.7 Lotus Domino 5.0.6 a Lotus Domino 5.0.6 Lotus Domino 5.0.5 -french Lotus Domino 5.0.5 Lotus Domino 5.0.4 a Lotus Domino 5.0.4 Lotus Domino 5.0.3 Lotus Domino 5.0.2 Lotus Domino 5.0.1 Lotus Domino 5.0 Lotus Domino 4.6.4 Lotus Domino 4.6.3 Lotus Domino 4.6.1 |
| Not Vulnerable: |
Lotus Notes Client 6.0.1 Lotus Notes Client 6.0 Lotus Notes Client 5.0.11 Lotus Notes Client 5.0.10 Lotus Notes Client 5.0.9 a Lotus Domino 6.0.1 Lotus Domino 6.0 Lotus Domino 5.0.12 Lotus Domino 5.0.11 Lotus Domino 5.0.10 Lotus Domino 5.0.9 a Lotus Domino 5.0.9 Lotus Domino 5.0.8 a Lotus Domino 5.0.8 -french Lotus Domino 5.0.8 Lotus Domino 5.0.7 a |
Discussion
Lotus Notes/Domino LDAP Service Vulnerabilities
The Lotus Notes/Domino implementation of the LDAP protocol is prone to issues that may result in the execution of attacker-supplied code.
These vulnerabilities are the issues reported in BID 3041, Lotus Domino R5 LDAP Service Buffer Overflow Vulnerabilities, and BID 3042, Lotus Domino R5 LDAP Service Format String Vulnerabilities.
These issues affect Lotus Notes/Domino R6 pre-release and beta versions as well as Lotus Domino R5.0.7 and earlier.
These issues were originally part of BID 7036. As new versions of Lotus Notes and Domino are also affected by this issue, a new BID has been assigned.
The Lotus Notes/Domino implementation of the LDAP protocol is prone to issues that may result in the execution of attacker-supplied code.
These vulnerabilities are the issues reported in BID 3041, Lotus Domino R5 LDAP Service Buffer Overflow Vulnerabilities, and BID 3042, Lotus Domino R5 LDAP Service Format String Vulnerabilities.
These issues affect Lotus Notes/Domino R6 pre-release and beta versions as well as Lotus Domino R5.0.7 and earlier.
These issues were originally part of BID 7036. As new versions of Lotus Notes and Domino are also affected by this issue, a new BID has been assigned.
Exploit / POC
Lotus Notes/Domino LDAP Service Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Lotus Notes/Domino LDAP Service Vulnerabilities
Solution:
These issues have reportedly been fixed by upgrading to R5.0.7a, R6 Gold, and 6.0.1. Administrators are urged to apply the upgrades and also follow best practices as well as all available mitigating strategies.
Fixes for Notes and Domino can be found at the Notes/Domino Downloads link in the References section.
Solution:
These issues have reportedly been fixed by upgrading to R5.0.7a, R6 Gold, and 6.0.1. Administrators are urged to apply the upgrades and also follow best practices as well as all available mitigating strategies.
Fixes for Notes and Domino can be found at the Notes/Domino Downloads link in the References section.
References
Lotus Notes/Domino LDAP Service Vulnerabilities
References:
References: